Executive brief
IBM Db2 Mirror for i is a database mirroring and high-availability solution used by enterprises to protect critical data on IBM i systems. A remote attacker can trigger a denial of service by exploiting an out-of-bounds read vulnerability, causing the database service to crash and become unavailable without requiring authentication or special privileges.
Technical details
The vulnerability is an out-of-bounds read (CWE-125) in IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. The flaw can be exploited remotely without authentication (AV:N/PR:N) to trigger a denial of service condition. An attacker can craft a malicious network request that causes the application to read memory beyond its allocated bounds, resulting in application crash or service disruption. IBM has released PTF (Program Temporary Fix) updates for all affected versions; patching is the recommended remediation.
Affected products
- IBM Db2 Mirror for i 7.4, 7.5, 7.6
Timeline
- 2026-09-04: disclosed
- 2026-09-01: patched: PTF updates available: 7.4 (SJ11153/SJ11193/SJ11207), 7.5 (SJ11152/SJ11194/SJ11206), 7.6 (SJ11151/SJ11195/SJ11205)